Remote HTML tag injection in Gaia System app

Related Vulnerabilities: CVE-2015-2745  

Mozilla Foundation Security Advisory 2015-73

Remote HTML tag injection in Gaia System app

Announced
August 6, 2015
Reporter
Muneaki Nishimura
Impact
High
Products
Firefox OS
Fixed in
  • Firefox OS 2.2

Description

Security researcher Muneaki Nishimura reported an issue with Gaia's System app which allows an attacker to inject HTML code into the System app's context via specially-crafted search links. The injection occurs when the user opens such malicious link in the browser and then presses the HOME button or uses the Show Windows function.

References